Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

151–160 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#151
post #65

One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…

Why do people keep saying it just works? It just works if you install their app, probably. But audio doesn't work at all in Firefox. That's not really just works for me.

Neither does Webex's browser version - even though I give it permissions, audio requires Webex to call me.

Latest Safari/macOS.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#152

Earlier quoted context omitted.

Please don't think of this in entropy terms alone. There is a massive usability difference between the two.

Do it in base 9000 with baby names and common words. "Join us in black raven deodorant daisy mega delta leo " Also create dud rooms with prerecorded conversation.

or honeypot rooms with super secret sounding military talk

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#153

Earlier quoted context omitted.

Why do people keep saying it just works? It just works if you install their app, probably. But audio doesn't work at all in Firefox. That's not really just works for me.

Yea, Hangouts is a lot more "it just works" than Zoom is for me. That being said, the quality of the actual calls on Zoom is _way_ better than Hangouts.

I mean, I don't really know how "consistently high call quality" is not the most important feature of any video chat application. My experience on hangouts has always been garbage. Delays, choppy sound, my machine starts going insane while rendering other people's live video. It may just work in the sense that you can immediately use it, but if even 20% of the time you use it the call quality sucks, then it's a crap product IMO.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#154

Earlier quoted context omitted.

Why do people keep saying it just works? It just works if you install their app, probably. But audio doesn't work at all in Firefox. That's not really just works for me.

Yea, Hangouts is a lot more "it just works" than Zoom is for me. That being said, the quality of the actual calls on Zoom is _way_ better than Hangouts.

Hangouts is going to be discontinued.

Hangouts meet is limited to 720p and sharing screen is limited to fcking 5 FPS.

Repeat with me, three times:

Hangouts scks for on-line presentations

Hangouts scks for on-line presentations

Hangouts scks for on-line presentations

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#155
post #149

Earlier quoted context omitted.

Why do people keep saying it just works? It just works if you install their app, probably. But audio doesn't work at all in Firefox. That's not really just works for me.

I'm not sure about "just works", but I am sure about "works" in the sense that is head and shoulders above every other video chat app I've used when it comes to audio and video quality, especially for large numbers of participants, audio sharing, document camera sharing, multiple participants sharing simultaneously, and there are plenty more. I've never used the web version, but it wouldn't surprise me if it's not th…

Yeah, the only other video app I've used that approaches the call quality is Slack. I've not tried to use that with more than a handful of people though.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#156

Earlier quoted context omitted.

I'm not a fan of Zoom... But the pile-on of grief is ridiculous. The "war dialing" issue is a great example. Webex has had the exact same "flaw" for a decade, with the exact same solution - set a meeting password. Other solutions like Google Meet or Skype have the "lobby" approach.

IMO, when it comes to security, the fact that other people have made the same mistake makes a design flaw more egregious, not less.

That is absolutely not an information security norm. Most security mistakes fall into common patterns.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#158

Earlier quoted context omitted.

The "just works" nature is why Zoom is popular. No one wants to have every meeting start with "Is Larry here? Oh, I think he's trying to dial in. I'm going to cancel this meeting and send out a new ID so he can dial in. Everyone watch for that so you can reconnect"

The second ID can be generated in addition to the first, primary ID.

You could even include the option to get approval - pop up says "Mx. Caller ID is calling from 555.555.5555. Approve?" Obviously there's no way to get in through random dialing. And if you get a pile of requests, provide a way to filter incoming numbers and disable the calling ID as soon as everyone is in.

That's even assuming that anti-DOS protection on the phone line is impossible.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#159

Earlier quoted context omitted.

s/users/ips/

With IPv6, I can assign myself a gazillion perfectly routable unique public IPs.

On a large enough level, this would have to be treated the same way as spam traffic currently is. You'd never ban anything smaller than a /64 with IPv6. Getting DOS from a /48 or /56? Ban them, or do exponential back-off for all IPs in the block. It's not that hard for a botnet to get a few hundred thousand IPv4 addresses either, but we haven't taken that as a reason to just roll over. The difference between each IP sending you 1 request / sec and 10000 requests / sec is still profound.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#160
post #97

Earlier quoted context omitted.

I've been thinking about security and usability for a while. IMO a big part of use-ability issues are related to interfaces people have to interact with. This is mainly concerning authentication and crypto related processes. I generally like the idea of smartcards, or having some physical thing you carry around which is used to authenticate with systems.

Two factor auth - some physical thing you carry around with you to authenticate with systems - is the very definition of decreasing usability in order to increase security.

Using a card as auth is not 2FA. I've hated some 2FA methods I've had to use (phone apps, RSA tokens), but when your auth method is just a yubikey or a key card, the usability experience is pretty excellent.
Post reply on HN